CVE-2021-41170 affects neoan3-apps/template versions prior to 1.1.1, where the template engine allows direct passing and execution of closures. This critical vulnerability (CVSS 9.8) enables remote attackers to execute arbitrary code by manipulating input values that share names with existing methods or functions, leading to full compromise of confidentiality, integrity, and availability. While a multi-step attack is plausible, there is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.1.1CPE matchmatch criteria | cpe:2.3:a:neoan:neoan3-template:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.